2021 CVE Vulnerabilities

23,451 CVEs published in 2021.

CVE IDSeverityCVSSDescription
CVE-2021-41931CRITICAL9.8The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnera...
CVE-2021-32600LOW3.8An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6...
CVE-2021-24856MEDIUM4.8The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which c...
CVE-2021-24854MEDIUM5.4The QR Redirector WordPress plugin before 1.6.1 does not sanitise and escape some of the QR Redirect fields, which could...
CVE-2021-24853MEDIUM4.3The QR Redirector WordPress plugin before 1.6 does not have capability and CSRF checks when saving bulk QR Redirector se...
CVE-2021-24852MEDIUM6.5The MouseWheel Smooth Scroll WordPress plugin before 5.7 does not have CSRF check in place on its settings page, which c...
CVE-2021-24851MEDIUM4.3The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and meta...
CVE-2021-24850MEDIUM5.4The Insert Pages WordPress plugin before 3.7.0 adds a shortcode that prints out other pages' content and custom fields. ...
CVE-2021-24847HIGH8.8The importFromRedirection AJAX action of the SEO Redirection Plugin – 301 Redirect Manager WordPress plugin before 8.2, ...
CVE-2021-24841MEDIUM4.8The Helpful WordPress plugin before 4.4.59 does not sanitise and escape some of its settings, which could allow high pri...
CVE-2021-24834MEDIUM5.4The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability which exists in th...
CVE-2021-24833MEDIUM5.4The YOP Poll WordPress plugin before 6.3.1 is affected by a stored Cross-Site Scripting vulnerability, which exists in t...
CVE-2021-24815MEDIUM4.8The Accept Donations with PayPal WordPress plugin before 1.3.2 does not escape the Amount Menu Name field of created But...
CVE-2021-24804HIGH8.8The Simple JWT Login WordPress plugin before 3.2.1 does not have nonce checks when saving its settings, allowing attacke...
CVE-2021-24802MEDIUM6.5The Colorful Categories WordPress plugin before 2.0.15 does not enforce nonce checks which could allow attackers to make...
CVE-2021-24796MEDIUM6.1The My Tickets WordPress plugin before 1.8.31 does not properly sanitise and escape the Email field of booked tickets be...
CVE-2021-24787MEDIUM4.8The Client Invoicing by Sprout Invoices WordPress plugin before 19.9.7 does not sanitise and escape some of its settings...
CVE-2021-24776MEDIUM4.3The WP Performance Score Booster WordPress plugin before 2.1 does not have CSRF check when saving its settings, which co...
CVE-2021-24772HIGH8.8The Stream WordPress plugin before 3.8.2 does not sanitise and validate the order GET parameter from the Stream Records ...
CVE-2021-24758HIGH8.8The Email Log WordPress plugin before 2.4.7 does not properly validate, sanitise and escape the "orderby" and "order" GE...
CVE-2021-24598MEDIUM4.8The Testimonial WordPress plugin before 1.6.0 does not escape some testimonial fields which could allow high privilege u...
CVE-2021-43337MEDIUM6.5SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_scrip...
CVE-2021-3939HIGH7.8Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallb...
CVE-2021-43012HIGH7.8Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker ...
CVE-2021-43011HIGH7.8Adobe Prelude version 10.1 (and earlier) are affected by a memory corruption vulnerability. An unauthenticated attacker ...

Check if your code is affected by 2021 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now